I'm trying to extract the total word count from field1 but am unable to find the correct solution. The format is:
field1: {'totalWordCount': 44891, 'totalUsers':49, 'usUsers':20, 'publishers':18, 'articlesByCountry': {'CA':124, 'US':50, 'AUS':19, 'NZ':2}, 'publishersbyCountry':{'CA':124, 'US':50, 'AUS':19}}
Theres much MUCH more to this field than I listed above but I am only interested in the total word count. Any idea how to extract this information?
I've tried |rex field=field1 "'totalWordCount': * " but get an error message "The regex "totalWordCount':*' does not extract anything. It should specify at least one name group. Format: (?<name>...).
Im still new to Splunk so bear with me!
... View more